PT-2025-38620 · Mattermost · Mattermost
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 10.5.x through 10.5.8
Mattermost versions 9.11.x through 9.11.17
Description
Mattermost fails to properly validate access controls, allowing any authenticated user to download sensitive files. This is possible through the board file download endpoint using UUID enumeration.
Recommendations
Update Mattermost versions prior to 10.5.9.
Update Mattermost versions prior to 9.11.18.
Exploit
Fix
DoS
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost